Legal

GDPR & data.

Last updated · 16 November 2025

This statement explains how Borlantrix OÜ processes personal data in line with the EU General Data Protection Regulation (GDPR). It complements our Privacy policy.

1. Data controller

Borlantrix OÜ, registered in Tallinn, Estonia, is the data controller responsible for the personal data described here. You can reach us through our contact form.

2. Personal data we process

  • Identity and contact data — name, email, company, and anything you send us.
  • Usage data — basic technical information about how you use our website.
  • Financial data (MoneyLights customers) — account, transaction and balance information accessed via open banking, and the documents you choose to upload.

3. Legal bases for processing

We process personal data under one or more of the following GDPR legal bases: your consent; performance of a contract; our legitimate interests in operating and improving our services; and compliance with legal obligations.

4. How we use your data

To provide and operate our services, reconcile documents and transactions, respond to your requests, keep our services secure, and meet legal and regulatory obligations. We do not sell your personal data.

5. Open banking & financial data (PSD2)

Bank access is provided through a regulated open-banking provider and is read-only — we can view account information to deliver the service, but cannot move money. Access is granted only with your explicit consent, and you can re-authorise or revoke it at any time.

6. Data processors & sharing

We use carefully selected third-party processors (for example hosting, open-banking connectivity, and document processing) under data-processing agreements. They may access personal data only to perform tasks on our behalf and may not use it for other purposes.

7. International transfers

Personal data is processed and stored within the European Union. Where a transfer outside the EU/EEA is unavoidable, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

8. Data retention

We keep personal data only for as long as necessary to provide our services and to meet legal, accounting and regulatory requirements, after which it is deleted or anonymised.

9. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data (“right to be forgotten”)
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time

To exercise any of these rights, contact us through our contact form.

10. Security

We protect personal data with encryption in transit and at rest, access controls, and auditable processes. No method of transmission or storage is completely secure, but we work to protect your data using appropriate technical and organisational measures.

11. Complaints

If you believe your data has been handled improperly, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — or with the supervisory authority in your country of residence.